Privacy Policy
Last updated: July 22, 2026 · Effective: July 22, 2026
At a glance
- We never ask for bank logins or card numbers. TripStacker has no bank connection and no account aggregation. You type in the cards and balances you want tracked. Nothing in the app can move money out of your accounts or make a purchase on your behalf.
- We do not sell your data. There is no advertising in TripStacker and no third-party tracking or analytics software in the app.
- The app does not ask for your location, contacts, photos, camera, or microphone. Those libraries are not in the app at all, so it cannot read them even if you wanted it to.
- Some things do leave the app. Your card and points context goes to Anthropic when you chat with Roux, and again overnight when a Claude model writes your daily brief. Your email goes to Stripe for billing. Push notifications go through Expo. Full list in section 4.
- Your data is stored in the United States.
- If you join the founding waitlist, that email is used only to tell you when TripStacker opens. Ask us and we delete it.
- You can delete all of it. Settings → Delete My Account inside the app, or email support@tripstacker.app and we will do it by hand. Either way it is permanent and cannot be undone.
Cosmo Solutions LLC ("we," "us," or "our") operates TripStacker, a mobile application that helps people track credit card rewards, watch points balances, and plan award travel. This Privacy Policy explains what we collect, how we use it, who else sees it, and how to get rid of it.
By creating an account or using TripStacker, you agree to the practices described here. If you do not agree, please do not use the service.
1. Information We Collect
1.1 Information you give us
- Account information: email address, username, and password. The password is stored only as a one-way bcrypt hash, so we cannot read it and cannot tell you what it is.
- Onboarding answers: the destination, home airport, cabin, timing, and experience level you pick when you set up. The preview screen you see before you create an account is generated on the fly and is not stored.
- Travel profile: home airport, dream destination, preferred cabin, self-reported experience level, time zone, and your chosen strategy mode. Also lifestyle preferences such as travel style, hotel tier, preferred airlines and hotels, and top spending categories. Some of these you pick directly. Some are inferred from what you enter.
- Credit card metadata: issuer, card name, open date, annual fee and fee date, earning categories and multipliers, per-card point balances, sign-up bonus tracking (spend target, spend so far, deadline, bonus size), your statement closing day and payment due day, and the card's display theme. We do not collect card numbers, CVV codes, or expiration dates.
- Card application history: issuer, card name, whether it is a business card, application and approval dates, status, whether the bonus posted, close date, product changes, and any notes you write. This is what we use to work out your 5/24 count.
- Points balances and loyalty programs: program name, currency code, issuer, current balance, and any nickname you give a loyalty account.
- Redemptions you log: points used, cash value, cents per point, redemption type, transfer partner, and your own description of the trip.
- Benefits and statement credits: which card credits you have used and when, enrollment status, reset periods, and any notes you add.
- Trip goals and bookings: origin and destination, travel dates and flexibility, number of travelers, cabin, trip type, points targets, preferred transfer partner, estimated cash cost, watch and alert settings, and your trip notes. If you enter them, this also includes hotel name, hotel dates, hotel program, and a booking confirmation number.
- Spending estimates: the monthly dollar amounts you enter by category (dining, groceries, gas, travel, transit, rent, streaming, online shopping, drugstores, other). These are your estimates, not transaction data. We have no way to see your actual statements.
- Roux conversations: the messages you send to Roux, the replies, and a record of any action Roux takes on your behalf inside the app (for example, adding a card or logging a redemption when you ask it to).
- Support requests and in-app feedback: ticket type, subject, and message. In-app feedback also records the screen you were on, what you expected, what actually happened, your app version and platform, and a contact email if you provide one.
- Card requests: the issuer and card name when you ask us to add a card we do not have yet.
- Notification preferences: which alerts you want, quiet hours, and a daily push cap.
- Learning and engagement state: lessons completed and quiz scores, tooltips seen, articles read, plays you saved or dismissed, sweet spots you saved along with your notes, and whether you have read, acted on, or dismissed a given alert.
- Founding waitlist email: if you give us your email address on this website to hear when TripStacker opens, we keep that address, along with which sign-up spot on the site you used, and we use it for one thing only, telling you when the app is available. The only thing about you on that form is your email address. The rest of it is machinery: a marker saying which spot you used, a hidden marker naming the form, and an anti-spam field that has to be left blank. There is no name, phone, or postal address field on it. The form is handled by Netlify, so the address sits in their form service and not in the app database. See section 4. Write to support@tripstacker.app and we will take you off the list and delete the address. We do not sell it, and we do not use it for anything but that one announcement.
1.2 Information collected automatically
- Push notification tokens: if you turn on notifications, we store the push token issued by Apple or Google through Expo, your platform, and your device name (for example, "iPhone 15").
- Notification delivery logs: the type, title, body, and delivery result of notifications we send you.
- Usage analytics, attributed to your account: events such as opening the wallet, sending a Roux message, or viewing a paid feature. These events are not anonymous. They carry your user ID, they are recorded on our own servers, and they are not shared with anyone. There is no third-party analytics service anywhere in TripStacker.
- Error and crash logs: when something breaks, the app sends us the screen context, error message, stack trace, platform, severity, and app version, linked to your account.
- Paywall and activity records: when a paid feature was shown to you and which one, and which calendar months your account was active. The active-month record is what the guarantee eligibility check reads. See section 5.
- AI-generated insights about you: your daily brief, today's move, card and trip and spending insights, next-card suggestions, route rankings, strategy suggestions, stack plays, card recommendations with match scores, redemption suggestions, trip opportunity matches, and deadline alerts. These are produced from the data above and stored on your account.
- Server request logs: our application logs the request method, path, response status, and how long it took. It does not record your IP address or your user agent. Our hosting providers keep their own access logs at the network edge, which do include IP addresses, under their own retention policies.
- This website: the pages on tripstacker.app serve their own typefaces from this site, so loading a page here makes no request to Google or to any other font host. Netlify, which serves these pages, records standard request logs for the same reason any web server does.
1.3 What we do not collect
This list is deliberately specific, because "we care about your privacy" is not information.
- No bank logins, bank account numbers, or account aggregation. TripStacker is not connected to Plaid, MX, Finicity, Yodlee, or any other aggregator. There is no code path in the app that could accept a bank credential.
- No credit card numbers, CVV codes, or expiration dates. There is no database field for them. Subscription payment happens on Stripe's own checkout page, so your card details never reach our servers.
- No Social Security numbers, government IDs, passports, or driver's licenses.
- No precise location. The app ships with no location library and requests no location permission. Responses from the TripStacker app server send a browser policy header that switches geolocation, camera, and microphone off outright. The airport codes in your account are text you typed, not device location.
- No contacts, photos, camera, or microphone. None of those libraries are in the app.
- No biometric data.
- No advertising identifiers and no cross-app tracking. There is no ad SDK, no attribution SDK, and no third-party crash-reporting SDK in TripStacker.
- No readable copy of your password.
- No award seat availability from licensed data partners. Where we show award pricing, it comes from published award charts, program pages, or our own calculations, and it is an estimate. See section 11.
2. How We Use Your Information
- To run the product: track your cards and balances, calculate what a redemption is worth, build your daily brief and alerts, and give Roux enough context to answer you usefully.
- To handle billing: create and manage your subscription through Stripe.
- To send you transactional email: account deletion confirmations and replies to feedback you submit.
- To keep score honestly: record what we surfaced to you and what you confirmed, which is what the ROI ledger and the guarantee are built on. See section 5.
- To improve the app: read our own first-party analytics and error logs to find bugs and dead ends.
- To answer support requests.
We do not use your information for advertising, and we do not sell it.
2.1 Automated processing we run ourselves
TripStacker runs background services that read your account data overnight to prepare your daily brief, your insights, your deadline alerts, and route data. These are our own systems, not third parties, and they authenticate with machine credentials we control rather than with your login.
Two things about them are worth stating plainly. First, they run on hardware we operate ourselves rather than inside the hosting environment described in section 4, so your account data is read on our own equipment as well as on our host's. Second, they are Claude sessions: preparing your brief means sending your account context to Anthropic, the same way a Roux conversation does. That third path is written out in section 4 alongside the other two.
3. How We Share Your Information
- Service providers: the companies listed in section 4, each receiving only what their job needs.
- Legal requirements: if required by law, subpoena, or court order, or where we believe in good faith that disclosure is necessary to protect our rights or someone's safety.
- Business transfers: if Cosmo Solutions LLC is acquired or merges, your information may transfer as part of that. We will give notice by email or in-app before your data becomes subject to a different privacy policy.
We do not sell, rent, or trade your personal information, and we do not share it with advertisers or data brokers.
4. Services We Use
This is the complete list of outside companies that receive any part of your data. If we add one, this page changes first.
Anthropic (Claude) · AI
Three things send data to Anthropic. All three are below.
Roux chat. When you send Roux a message, we send that message plus a context block containing: your card names and issuers, annual fees, per-program points balances and program names, your total points, home airport, 5/24 application count, subscription tier, sign-up bonus progress in dollars, expiring statement credits by card and benefit name, best card per category, available transfer partners, active transfer bonuses, your trip goals, experience level, and strategy mode. We also send your last 20 messages in that conversation so Roux does not lose the thread.
Card recommendations. When you ask for a card recommendation, we send your current card list, your 5/24 status, your active trip goals with points needed, your strategy mode, and your top three spending categories with the monthly dollar amounts you entered.
Your daily brief and insights. This one happens overnight, without you asking. The background services described in section 2.1 are Claude sessions running on hardware we operate. To write your brief they read your profile, your cards and their open dates, your points balances, your trip goals, up to two years of your card application history, your spending estimates, and your five most recent logged redemptions, and that context goes to Anthropic. What comes back is stored on your account as your brief, your card and spending insights, your next-card suggestions, and your strategy suggestion, along with a note of which model wrote it.
We do not send Anthropic your email address, username, password, or location. Your account ID travels on the overnight path only, because that is how the service asks our own systems for the right person's context. On the two paths you trigger yourself, it is not sent.
Under Anthropic's commercial API terms, data sent through the API is not used to train their models. Anthropic privacy policy
Stripe · Payments
Stripe runs our subscription billing. When you subscribe, Stripe receives your email address, your username as the customer name, and your internal TripStacker user ID as metadata. Your payment card details go from your browser straight to Stripe's hosted checkout page and never touch our servers. We store back only a Stripe customer ID and subscription ID. Stripe privacy policy
Resend · Email delivery
Resend sends our transactional email. It receives more than an address, so it is worth being precise: an account deletion email carries your email address and username. When you submit in-app feedback, the notification to our support inbox carries your email address, subscription tier, user ID, platform, app version, the screen you were on, and the full text of what you wrote, with your address set as the reply-to. Resend privacy policy
Expo · Push notifications
TripStacker is built with Expo. When we send you a notification, Expo's push service receives your push token and the notification itself, which can name a card, a points amount, or a trip destination. Your device name and platform are stored by us and are not sent to Expo. You can switch push off in your device settings at any time. Expo privacy policy
Perplexity · Research
We use Perplexity's research API to keep award route data, card offers, and transfer bonuses current. Most of those queries are generic and carry nothing about you. One path is different and we want to name it: if you plan a trip to a destination we have not researched yet, the destination and cabin class you chose are put into a research query. No identifier travels with it. Perplexity does not receive your email, user ID, balances, or card portfolio. Perplexity privacy policy
Railway · Application hosting
Our application server runs on Railway, in the United States. Railway processes every request the app makes and keeps standard access logs, including IP addresses, under its own retention policy. Railway privacy policy
Supabase · Database hosting
Your data at rest lives in a PostgreSQL database hosted by Supabase in the United States (US East). That includes your account, password hash, cards, balances, trip goals, Roux history, ledger, and logs. Supabase privacy policy
Netlify · This website
The pages on tripstacker.app, including this one, are served by Netlify, which records ordinary web server logs (IP address, user agent, requested path) for anyone who loads a page here. The founding waitlist is a Netlify form, so if you sign up, your email address and which spot on the site you used are submitted to Netlify and held in their form service until we remove them. Netlify has no access to the app database, and nothing about a TripStacker account passes through it. Netlify privacy policy
Not used
For the avoidance of doubt: TripStacker has no advertising network, no analytics vendor, no crash-reporting vendor, no map or geolocation service, and no data broker relationship. Nothing in the app sends your data to a social network.
Typefaces are not a third party here either. This website serves its own font files from the same place it serves the page, and the mobile app bundles its fonts locally. Neither one calls Google Fonts or any other font host, so no font provider learns that you loaded a page, including this one.
5. Your ROI Ledger and Guarantee Data
TripStacker keeps a running ledger of what it has found for you. It is the basis of our 10× guarantee, so it is worth explaining exactly what gets written down.
For each find we put in front of you, we record: the type of find and the feature it came from, the moment it was surfaced, the moment you viewed it, the moment you acted on it if you did, the dollar value we assigned, the points amount and the cents-per-point rate we used, and a short plain-language receipt naming the card or currency involved so you can check our arithmetic. We also record whether the find was a baseline item that was already true before you set up.
We record your answers. When we ask whether a find was useful, we store your yes, no, or "already planned." A "no" removes the item from your confirmed total. It does not remove it from the guarantee number, because the guarantee is about what we surfaced, not about what you agreed with.
We record two eligibility facts: whether your wallet is set up (at least one active card and one points balance) and which months your account was active. Those are the only two conditions on the guarantee, and your status against them is visible to you all year rather than sprung on you at the end.
We record win moments: when your ledger crosses its target, we store the moment it happened, the amounts, your tier at the time, and whether you accepted or declined anything we offered.
This data is used to run the ledger, to decide guarantee claims, and to check our own honesty about whether the product is worth what it costs. It is not shared with anyone. If you cancel, your ledger stays with your account, frozen and visible. If you delete your account, it is deleted with everything else.
6. Data Retention & Deletion
Some of these windows are enforced by scheduled jobs. Where nothing automatically deletes something, we say so rather than implying a cleanup that does not happen.
- Account data: kept until you delete your account.
- Roux conversations: we keep your most recent 100 messages for up to 365 days. Anything older than your most recent 100 messages is deleted after 90 days. All of it is deleted immediately when you delete your account.
- Usage analytics events: deleted after 90 days.
- Notification delivery logs: deleted after 60 days.
- Error and crash logs: deleted after 30 days.
- Paywall records: deleted after 180 days.
- Expired and revoked login tokens: purged several times a day.
- Everything else on your account (cards, balances, trip goals, redemptions, benefit tracking, spending estimates, AI-generated insights, ROI ledger, push tokens, support tickets, feedback): kept for as long as your account exists. We do not currently run an automatic expiry on these, and we would rather tell you that than quote a number no job enforces.
- Founding waitlist email: kept until the launch email goes out or you ask us to remove it. Nothing expires it on a timer.
- Server access logs: we do not keep our own. Our hosting providers keep theirs under their published retention policies.
- Stripe records: Stripe retains payment records independently, as it must for financial and tax obligations.
Deleting your account
You can delete your account and everything attached to it:
- In the app: Settings → Danger Zone → Delete My Account. You will be asked for your password to confirm.
- By email: write to support@tripstacker.app from the address on the account.
Deletion cancels any active subscription, removes your account and all of the data described in section 1, and sends a confirmation to the address on the account. It is irreversible. Your analytics events are deleted too, not anonymized and kept.
The in-app button does the work in one step, while a request by email is done by hand and takes as long as it takes us to read it. If the in-app deletion ever returns an error, write to support@tripstacker.app and we will finish it for you. A failure on our side is not a reason you have to keep an account you asked us to close.
7. Data Security
- Passwords are hashed with bcrypt at cost factor 12 and are never stored in readable form.
- Traffic between the app and our servers is served over HTTPS, and our production responses send a strict transport security header.
- Sign-in uses a short access token that expires after 15 minutes, paired with a refresh token that lasts 7 days. Refresh tokens are stored only as one-way hashes and are rotated every time they are used, so a used token is dead. Logging out revokes every refresh token on your account. To be plain about what this means: as long as you open the app at least once a week, your session renews and keeps going. There is no hard maximum session length.
- On iOS and Android, your tokens are held in the operating system's secure keystore, not in ordinary app storage.
- Sign-in, account deletion, and chat endpoints are rate limited to blunt automated attacks.
- Payment card data is handled entirely by Stripe and never reaches our servers.
- Database connections are encrypted and restricted to authenticated application connections.
- Passwords must be at least 8 characters. We do not offer two-factor authentication yet. If we add it, this line changes.
No method of electronic transmission or storage is completely secure. We do what is described above, and we will not claim more than that.
8. Your Rights
Everyone
- Access: your cards, balances, trips, ledger, and profile are visible in the app at any time.
- Correct: edit any of it in the app.
- Delete: remove your account and all associated data. See section 6.
- Export: email support@tripstacker.app from your account address and ask for an export. We will send you your data in a machine-readable file. We aim to do this within 30 days.
California residents (CCPA / CPRA)
- Right to know the categories and specific pieces of personal information we have collected in the past 12 months, where it came from, why we collected it, and who we shared it with.
- Right to delete your personal information, which you can do yourself in the app.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing. There is nothing to opt out of. We have never sold personal information and we do not share it for cross-context behavioral advertising.
- Right to non-discrimination for exercising any of these rights.
Write to support@tripstacker.app. We will verify your identity before acting and respond within 45 days.
Categories of personal information collected (CCPA disclosure)
- Identifiers: email address, username, user ID, Stripe customer ID, push notification token, device name.
- Commercial information: subscription tier and billing history, self-reported monthly spending by category, points balances, redemptions you log, and booking details you enter.
- Internet or network activity: first-party usage analytics, paywall records, active-month records, error logs, and onboarding progress.
- Inferences: travel preferences derived from your input, AI-generated insights, card keep-or-cancel verdicts, earning projections, match scores, and strategy recommendations.
We have not sold any personal information. We have disclosed personal information to the service providers named in section 4 for the purposes described there.
9. Age Requirement
TripStacker is for adults. You must be at least 18 years old to create an account, and the service is not directed at or intended for anyone under 18. We do not knowingly collect information from anyone under 18, and if we learn that we have, we delete the account and its data promptly.
If you are a parent or guardian and you believe a minor has created an account, write to support@tripstacker.app and we will remove it.
10. International Users
TripStacker is operated from the United States, and our application server and database are both located in the United States. If you use TripStacker from elsewhere, your information is transferred to, stored in, and processed in the United States, and you consent to that transfer by using the service. The protections described in this policy apply regardless of where your data came from.
11. AI and Estimates
TripStacker uses Anthropic's Claude to generate parts of what you see: Roux's replies, your daily brief, card keep-or-cancel verdicts, strategy suggestions, and card recommendations. Your daily brief carries an AI label in the app. The rest of that list is not badged screen by screen, which is why it is written out here instead.
AI output can be wrong. Transfer ratios, promotion dates, award pricing, and card terms change constantly, and a model can repeat something stale with complete confidence. Verify anything that matters with the airline, hotel, or card issuer before you act on it.
Award pricing in TripStacker is an estimate. We do not show live award seat availability, and we do not hold live availability data. Prices come from published award charts, program pages, or our own conservative calculations, and the valuations we use are published so you can see the number we applied. An estimate is not a seat, and a seat is not a booking.
12. Changes to This Policy
We may update this policy. When we make a material change, we update the "Last updated" date above and give in-app notice where it matters. Continuing to use TripStacker after a change takes effect means you accept the updated policy.
13. Contact Us
Questions about this policy, a data export, or a deletion request:
Cosmo Solutions LLC
Email: support@tripstacker.app
App: TripStacker
Web: tripstacker.app/contact